Fulfilling the promise of NFV with reconfigurable computing

With so many new technologies vying for attention, it can be difficult for CISOs to know which ones merit attention. Will this solution save time? Will it make our organisation more productive, or enable us to do things we couldn’t otherwise do? These questions need to be considered before adopting software-defined networking (SDN) and network functions virtualisation (NFV).

What makes these technologies appealing is their ability to separate software from hardware, which eschews the vendor lock-in that has been the norm. So then, the main question is not about budget but about an organisation’s ability to overcome the challenges of these methods so organisations can realise their full value.

At the time enterprises, mobile operators and data centers began building their own network infrastructure, they used the typical customised hardware and software offered on the market. Example applications include network gateways, switches, routers, network load balancers, varied mobile applications in the mobile core; radio access network such as vEPC (virtual evolved packet core), vCPE (virtual customer premise equipment) and vRAN (virtual Radio Access Network); and security applications like firewalls, NGFW, IDS/IPS, SSL/IPsec offload appliances, DLP and antivirus applications, to name just a few. 

Instead of needing to purchase proprietary appliances to run each networking application, it is much more cost-efficient to support these functions as software applications, called virtualised network functions (VNFs), running on virtual machines or in containers on standard servers. That’s the idea behind NFV. Moving away from discrete, cus­tomised architectures to a more consolidated “x86-only architecture” promises to reduce costs, simplify deployment and management of net­working infrastructure, widen supplier choice and, ultimately, enable horizontal scale-out in the networking and security market.

It’s not a sure bet that the throughput and latency demands that today’s applications require can be handled by applications in software on standard platforms without allotting significant CPU resources to address the issue. Operators are realising that the cost savings that NFV promises are offset by the need to deploy entire racks of compute resources at a problem that a single appliance could previously support. The CPU and server costs, rack space and power required to meet the same performance footprint of a dedicated solution end up being as expensive as or more than custom-designed alternatives. The vision of operational simplicity and dramatically lower total cost of ownership are still a dream on the horizon.

Along comes 5G

As if the performance and scaling problems that operators face with generic NFV infrastructure (NFVi) weren’t enough to worry about, the presence of 5G networks will make these concerns worse. The move to 5G brings new requirements to mobile networks, creating its own version of hyperscale networking that is needed to meet the performance goals for the technology, but at the right economy of scale. Numerous factors are fundamentally unique to 5G networks when compared to previous 3G/4G instantiations of mobile protocols. The shorter the distance, the higher the frequency – thus, the more bandwidth that can be driven over the wireless network.

But wait – it gets worse. 5G will also mean a huge increase in the number of users/devices (both human and IoT), which fundamentally affects the number of unique flows in the network and necessitates very low latency requirements. 5G also promises lower energy and cost than previous mobile technologies. These 5G goals, when realised, will drive the application of wireless communications to completely new areas never seen before.

Rapid scaling

If they are going to meet performance goals, network operators now see that they will need data plane acceleration based on FPGA-based SmartNICs in order to scale virtualised networking functions (VNFs). This technique offloads the x86 processors that are hosting the varied VNFs to support the breadth of services promised.

When SmartNIC acceleration supports virtual switching, this set-up has been shown to be the highest-performing and most secure method of deploying VNFs. Virtual machines (VMs) can use accelerated packet I/O and guaranteed traffic isolation via hardware while maintaining vSwitch functionality. FPGA-based SmartNICs specialise in the match/action processing required for vSwitches and can offload critical security processing, freeing up CPU resources for VNF applications.

Functions like filtering, intelligent load balancing, virtual switching, flow classification and encryption/decryption can all be performed in the SmartNIC and offloaded from the x86 processor housing the VNFs while, through technologies like VirtIO, be transparent to the VNF, providing a common management and orchestration layer to the network fabric.

A novel configuration

Network infrastructure has changed so dramatically and so much more is being asked of it that organisations cannot operate with networking and security solutions that are expensive, hardened and fixed-function.

The technique to overcome the challenges that are facing NFV deployments requires reconfigurable computing platforms based on standard servers capable of offloading and accelerating compute-intensive workloads, either in an inline or look-aside model to appropriately distribute workloads between x86 general-purpose processors and software-reconfigurable, FPGA-based SmartNICs optimised for virtualised environments.

The environment that results from combining low-cost server platforms and FPGA-based SmartNICs is one that enables huge throughput and support for many millions of simultaneous flows. CISOs that have struggled to implement NFV now have the option to use this novel framework, with the capabilities and the speed they need.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Bringing the Next 100 Million People to Blockchain | @CloudEXPO @CelsiusNetwork #FinTech #Blockchain #Bitcoin #Ethereum #SmartCities

The Crypto community has run out of anarchists, libertarians and almost absorbed all the speculators it can handle, the next 100m users to join Crypto need a world class application to use. What will it be? Alex Mashinsky, a 7X founder & CEO of Celsius Network will discuss his view of the future of Crypto.

read more

Serverless Architecture on AWS | @CloudEXPO @RapidValue #CloudNative #Serverless #AWS #DataCenter #Docker #Kubernetes

Serverless Architecture is the new paradigm shift in cloud application development. It has potential to take the fundamental benefit of cloud platform leverage to another level.

“Focus on your application code, not the infrastructure”

All the leading cloud platform provide services to implement Serverless architecture : AWS Lambda, Azure Functions, Google Cloud Functions, IBM Openwhisk, Oracle Fn Project.

read more

ServerlessSUMMIT at @CloudEXPO Silicon Valley | @IoT2040 #CloudNative #Serverless #DevOps #Docker #Kubernetes

As you know, enterprise IT conversation over the past year have often centered upon the open-source Kubernetes container orchestration system. In fact, Kubernetes has emerged as the key technology — and even primary platform — of cloud migrations for a wide variety of organizations.

Kubernetes is critical to forward-looking enterprises that continue to push their IT infrastructures toward maximum functionality, scalability, and flexibility.

As they do so, IT professionals are also embracing the reality of Serverless architectures, which are critical to developing and operating real-time applications and services. Serverless is particularly important as enterprises of all sizes develop and deploy Internet of Things (IoT) initiatives.

read more

SAP bets big after breaking €20bn in 2018 cloud and software revenues

SAP broke €20 billion in yearly cloud and software revenues in 2018, hitting or exceeding its raised outlook metrics in the process – and the company wants more, targeting €35bn in total revenue by 2023.

The Q4 2018 financial results saw total cloud and software revenues hit €6.3 billion (£5.5bn), representing 85% of total revenues that quarter. Naturally this statistic is somewhat obfuscatory – as regular readers of this publication will recognise, many of the largest cloud providers do it – but other stats are available. New cloud bookings for the whole of 2018 hit €1.8bn, a 25% increase on the previous year, while CEO Bill McDermott said cloud revenue grew 40% in Q4, and 38% across the full year.

Speaking to analysts in an earnings call, McDermott put the figure of ‘cloud users’ SAP holds at 180 million, and was bullish at the company’s progress, particularly after the acquisition of Qualtrics for $8 billion first announced in November.

“SAP has only winning businesses in the portfolio,” said McDermott. “Every strategic asset in the company is growing. And looking back, the belief was enterprise customers would only want to rent software. But SAP embraced the software as a service business model early on and we’re growing the cloud faster than competition – and that includes Oracle, Salesforce.com and Workday to name a few.”

Chief financial officer Luka Mucic noted that public cloud, or software and platform as a service gross margin, improved solidly during 2018. “Looking forward, we expect to realise the benefits from our platform convergence in the first half of 2019 with further acceleration in the second half,” he said. “This will set us up with full scalability going into 2020 and beyond.”

McDermott joked that he might sign his emails off in future with ‘XO’, another reference to the Qualtrics acquisition. SAP sees the research management software provider as a key piece in their jigsaw to combine operational data (O), from their side, with experiential data (X) from Qualtrics.

“This is the only strategy for SAP as we look at our bright future,” added McDermott. “And we know it’s where the world is going. Experienced management is the future and SAP owns it.”

You can read the full Q4 statement here (pdf).

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Rubrik security slip-up exposed masses of its corporate clients’ data


Connor Jones

30 Jan, 2019

Data management company Rubrik was found to have an unsecured server that exposed, in some cases, sensitive client information.

The server itself wasn’t password protected which meant that anyone who knew the location of the server could access it, according to TechCrunch. It held tens of gigabytes of data including client names, email addresses, email signatures and their case work.

Rubrik, which is valued at $3.3 billion, has some incredibly high-profile clients whose information was on the exposed database which include Deloitte, Shell and the NHS among others.

It wasn’t just the high-profile clients that belonged on the database, all of its corporate clients resided on there and the database was indexed on Shodan, a search engine for exposed devices and databases.

In addition to the names and contact details, contents of emails relating to issues and complaints between clients and Rubrik were also stored on the dedicated client portion of the exposed server. Some emails also included sensitive information about Rubrik’s clients’ setup and configuration.

Rubrik has said it took the database offline within an hour of becoming alerted to the issue, the data from which dated back to October 2018 according to email timestamps.

“While building a new solution for customer support, a sandbox environment containing a subset of our customer corporate contact information and support interaction data was potentially accessible for a brief period of time,” said a spokesperson for Rubrik. “We rectified this issue immediately.”

“We also confirmed that no customer-owned data was exposed,” the spokesperson added. “Other than the security researcher who discovered this issue, no one has accessed this environment”.

This comes as fairly ironic news as Rubrik recently announced that it will expand into the security and compliance market.

On that note, you may have picked up on the fact that some of Rubrik’s clients are based in Europe which means GDPR could come into play. The data giant could face a fine of up to 4% of its annual global revenue for exposing data it is responsible for.

It would be a big blow to the up-and-coming star in data management which raised $261 million from venture capital firms earlier this month and was also listed in the top 5 IPO prospects for 2019 by Mosaic Score.

Global Microsoft outage leaves users unable to login


Keumars Afifi-Sabet

30 Jan, 2019

A host of Microsoft’s cloud services including Azure Government Cloud and LinkedIn sustained a global authentication outage just a few days after users were blocked from accessing Office 365 in Europe.

Users in parts of Europe, the US, as well as Australia and Japan were blocked from logging into their services between 9pm GMT yesterday and the early hours of this morning due to authentication issues.

A host of Microsoft Cloud services including Dynamics 365 and Office 365, as well as US Government cloud resources, were out of action for a few hours due to problems with its authentication infrastructure.

According to the outage detection service downdetector, the issue may have affected a wide range of services including Skype, OneDrive, Office365, and Outlook.com – which all experienced spikes at roughly the same time. Users also complained across social media about difficulties logging into these platforms.

The issue, which has now been resolved, involved users attempting to log into new sessions, with the Azure status page indicating it concerned an internal DNS provider, describing the issue as ‘Level 3’ after an investigation. Microsoft says that engineers mitigated the outages by failing over CyberLink DNS services to an alternative provider.

These issues were resolved shortly after midnight this morning, but lasted at least a few hours, affecting users in predominantly the Eastern hemisphere who were getting into the crux of their working days.

The global outage arose just five days after Microsoft customers were unable to access their Office 365 accounts for a full working day in Europe.

The company confirmed on Thursday, after initially maintaining that services were running smoothly, that its cloud-powered productivity suite was experiencing difficulties, with the continental outage lasting around nine hours in total. 

This rocky start to the new year reflects a series of outages that Microsoft had sustained with its cloud services in the last few months of 2018, as the Windows-manufacturer struggled to provide 100% reliability. 

Understanding Kubernetes today: Misconceptions, challenges and opportunities

Any discussion of Kubernetes is best started with an understanding of why we need Kubernetes. Kubernetes helps us manage containers, which dominate application development now because they enable portability, faster application development, and greater independence for developers. Once we started using containers in great volume, we needed a way to automate the setup, tear down, and management of containers – that's what Kubernetes does.

The industry has developed other orchestrators, but Kubernetes has emerged as the de facto standard for container orchestration. As much as nearly a year ago, 69% of organisations surveyed by the Cloud Native Computing Foundation (CNCF) were using Kubernetes to manage containers. Kubernetes started with the technical credibility of coming out of Google, and thousands of contributors have increased the robustness, scalability, and security features of Kubernetes.

A series of data points highlight the growth in popularity of Kubernetes. All the cloud providers offer a managed Kubernetes service. Amazon executives highlighted at the company’s recent AWS re:Invent conference that its managed Kubernetes service, AWS EKS, is the fastest growing service AWS has ever released. KubeCon, the industry conference hosted by the Cloud Native Computing Foundation (CNCF) has doubled in attendance every year, with more than 8000 people attending the recent North America conference. And scan any tech job aggregator like Indeed.com and you’ll see 1000s of companies seeking Kubernetes expertise for their IT architecture teams.

The mergers and acquisitions market provides another lens into the popularity of Kubernetes. IBM’s recent acquisition of Red Hat for $34 billion provides another indication of the popularity of Kubernetes. Most industry analysts said OpenShift, Red Hat’s commercial distribution of Kubernetes, drove a significant portion of that valuation. Also, recently, VMware acquired Heptio, which provided another popular distribution of Kubernetes. The purchase price is rumored to be $550 million, an astonishing amount for a company that hadn’t had the chance to generate much revenue yet.

Common misunderstandings about Kubernetes

Despite the massive popularity of Kubernetes, misunderstandings about the platform persist. One centres around how to work with Kubernetes. Most people running open source software have a “DIY” or “do it yourself” perspective – they’re used to digging into software and tuning all the dials and twisting all the knows. So, people often think they should be working directly in the Kubernetes platform. Often that’s not the best approach, however.

As Kubernetes continues its market dominance, organisations need to look for ways to apply a UI layer to the orchestrator to simplify management and security

Building support for high availability (HA) and resilience into Kubernetes, for example, is complicated – these areas provide a great reason to leverage abstraction layers on top of Kubernetes to simplify its operations and make it run in a more robust manner. People talk about Kubernetes needing a UI layer – another interface into it to make kind of needs a UX layer on top. A lot of the managed Kubernetes services provide this abstraction layer for getting the fundamentals set up, like setting up the master, the API server, and resilient data stores.

The same goes for the security layer. Kubernetes has a lot of power controls built in for networking policy enforcement, for example, but accessing them natively in Kubernetes means working in a YAML file. Having tooling on top that visualises the networking layer, as we do in the StackRox platform, makes the power of Kubernetes far more accessible to enterprises in a way similar to how Google Kubernetes Engine makes the control plane of Kubernetes more accessible.

Securing Kubernetes

Kubernetes provides powerful security capabilities around secrets management and network policy enforcement. Digging into network policy enforcement, you can use Kubernetes to limit what resources each asset can reach. By default, Kubernetes allows all assets to talk to all other assets, because the premise of Kubernetes is that it’s meant to aid application development, and as developers craft the microservices that are the building blocks for applications, Kubernetes defaults to letting all those services communicate.

Because the developers are working in Kubernetes, the security team should also use Kubernetes to help tighten down the environment – to limit those communications paths to reduce the blast radius if an attacker got in. Moving to least privilege is a fundamental tenet of security – any person or asset should be allowed to do only the functions necessary to its role and no more. Look for a container security platform that simplifies the process of moving Kubernetes to a least privilege model. The platform should highlight the allowed communications between assets, simulate new network policies, and recommend updated configurations that support least privilege and harden the environment.

Bringing it all together

As Kubernetes continues its market dominance, organisations should look for ways to apply a UI layer to the orchestrator to simplify functionality such as management and security. Despite its inherence security functions, Kubernetes also increases the attack surface, so organisation should look for security platforms that integrate deeply with Kubernetes to make accessing its security functions easier and provide mechanisms for reducing its attack surface.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

How big data will change our lives

30 Jan, 2019

The phrase “big data” itself unnerved some of us a few years ago. And in light of recent worries concerning improper use of personal data, it’s taken on a sinister note for some. But the increasingly huge wealth of data about every aspect of life now available is one of the miracles of the connected computing era. We create 2.5 quintillion bytes of data every day, and that figure is also increasing daily. Despite the valid concerns about the misuse of personal data, all this information has the potential to revolutionise every area of our lives in beautifully beneficial ways.

The key ingredient is how you interpret and use all that data and we’re only just scratching the surface of what can be achieved with all the information. This is because big data is by definition beyond what traditional data-processing application software is designed to cope with. Research group Gartner’s Doug Laney coined the “3 Vs” to define big data back in 2001, standing for volume, velocity and variety. More recently variability, veracity and complexity have been suggested as additions.

What all these parameters are intended to illustrate is that it’s not just the amount of information that defines “big data”, but the speed at which it is arriving and the many different categories involved. Both the number of cases and the attributes for each one are orders of magnitude larger than previous data repositories. For example, wearables such as sports watches are collecting a wealth of information about people’s exercise habits and this often includes details like heart rates, location throughout a routine, cadences for cycling and running, and even blood oxygen levels.

Businesses now rely on the data they collect about their customers, so how this is used effectively by employees is paramount. The modern era of “digital” companies like Google, Facebook, Uber and Airbnb are more about how they use the data they collect than what they actually trade in or produce. There is a huge debate about the relationship between these kinds of companies and their users. In the case of pure data companies like Facebook, there is a more complex value exchange than traditional commerce. With the latter, the customer parts with money and receives a product or service in return.

But with a company like Facebook or Google, the end user doesn’t part with any money for the service they receive – such as social network media sharing or internet search results, email and cloud-based applications. Instead, what they exchange is their personal information. Data is the currency that users spend to receive the services provided. Regulatory frameworks like GDPR have arisen in recognition of the value of the data users part with when they access these services. However, many users don’t realise (or care) how much personal data they are giving away. The entertainment and social interaction they receive in return is sufficient to make them feel that they get more back than they spend.

All businesses collect data about their users, and whether or not users feel uncomfortable about this depends on how this information is used, as well as what they get in return. At one end of the scale, passing on personal details for third-party marketing purposes is not usually appreciated. However, the ability to use a system like Apple Pay to order a food delivery using just a thumbprint to verify identity and transfer the necessary funds is much more convenient than digging in your pocket for a credit card. Handing over your credit card details to Apple is necessary for this convenience. When this process also passes on your address details to the delivery company automatically, it’s an even more seamless experience.

This is just the smallest tip of the iceberg. Big data promises to make emerging services like car sharing meet end user needs more seamlessly. Putting aside those who own cars for enthusiast reasons, the biggest barrier preventing people from switching to car sharing from personal ownership is the fear of not having their vehicle available exactly when they need it. But accurate predictive analysis of behaviour, bringing in factors like weather, current events and even personal habits, could mean that there is always a car nearby when required, because the data analysis calculated that you would. Perhaps a little spooky, but undeniably convenient. The ability of services like Uber and Airbnb to match provision with need is already showing the potential from well-honed analysis of behavioural data. Similarly, Amazon’s grasp of supply-chain flow allows it to deliver many products the next day, or even the same day.

Over the next few years, the amount of information we share and is amassed about the world around us is set to increase exponentially. Virtually all companies can potentially benefit from collecting the right data and analysing it appropriately. Internet of Things devices, like per-room home thermostats, per-socket power consumption monitoring, health monitoring patches and connected cars with real-time tracking, are set to proliferate. These will be providing huge volumes of data and new possibilities of analysis. The relationship between health and lifestyle, for example, can be explored continually to find improvements.

The bandwidth available to wireless devices will be an order of magnitude higher, too, with 5G already being tested in the UK, for example O2’s trial at the O2 Arena in North Greenwich, London. When 5G is eventually introduced it will allow wireless data speeds up to 1,000 times faster than 4G, and promises much lower latency too. In combination with the Internet of Things revolution, 5G will further enable the exponential growth of data accumulation, particularly real-time supply from intensive sources like video surveillance.

Big data also has the power to make jobs easier for workers in critical areas such as emergency services. Police in the UK, for instance, are already using ‘predictive crime mapping’, where huge amounts of data on crime types, locations and times are processed to generate hotspot maps showing officers where crime is most likely to occur. The NHS, too, has a rich pool of patient data on which to draw. This can aid doctors in everything from recognising the warning signs of diabetes to effectively managing patient flow and ward demand during busy winter months.

As we mentioned at the beginning of this feature, there are potential dangers from all this data. But with the right safeguards and observance of regulations, the fears people have can be allayed, allowing the benefits to shine through. O2, in its business blog post “What does the future of big data look like?”, highlights how regulations like GDPR can be viewed as an opportunity for companies, rather than a threat. Testing your data for compliance should be seen as a chance to review what is being collected and how it is used, with the aim of finding untapped potential. Rather than just being an unwanted extra cost, this process can truly uncover the beautiful future possibilities of big data.

Discover how O2’s technology is helping businesses empower their workforce.

Cisco reveals new tools and networking products for IoT


Clare Hopping

30 Jan, 2019

Cisco has confirmed its commitment to the IoT, with the announcement of new developer tools, networking products and partnerships to establish its position in the IoT world.

The first major facilitator is the launch of its Catalyst industrial switches and integrated services routers that have been specifically built for IoT environments. Both tools are managed by Cisco DNA Center that allows businesses to manage their infrastructure in a single area, even if they’re being used across environments.

“In IoT, the conversation is about business outcomes. It starts with secure connectivity as the foundation of every IoT deployment. By providing scale, flexibility and security, we’re turning the network into a secret weapon for our IoT customers,” said Liz Centoni, senior vice president and general manager, IoT at Cisco.

An extension of Cisco’s IoT developer tools within its DevBet IoT developer centre will make it easier for creators to integrate Cisco’s IoT networking solutions into their apps and services.

“With a new DevNet IoT developer center, we’re empowering thousands of partners and developers around the world to build upon our IoT platform,” Centoni said.

Cisco also said it wants to work closer with resellers, ISVs, manufacturers and service providers to spread the reach of its IoT programme. By providing the hardware and software tools businesses need to embrace the IoT world, Cisco believes it can make a difference to a whole host of industries, particularly manufacturing, utilities and remote and mobile assets. It has recently unveiled validated designs for those industries to get them up and running faster.

“We closely collaborated with Cisco on Cisco’s new compact, low-power industrial router to meet the stringent environmental and safety standards used in the utilities industry,” said Didier Hinguant, telecom director at Cisco partner Enedis.“We operate and deploy our connected grid with thousands of Cisco routers via Field Network Director zero touch provisioning, with an agile, highly secure and future proof network using IPv6 to address our scalability constraints.”

The cloud news categorized.